·áÌï½ðÈÚ·þÎñ¹«Ë¾Ôâµ½Medusa¹¥»÷²¢±»ÀÕË÷800ÍòÃÀÔª
°ä²¼¹¦·ò 2023-11-20¾ÝýÌå11ÔÂ16ÈÕ±¨Â·£¬£¬£¬£¬£¬£¬£¬£¬·áÌï½ðÈÚ·þÎñ¹«Ë¾(TFS)Ôâµ½¹¥»÷£¬£¬£¬£¬£¬£¬£¬£¬ÆäÔÚÅ·Ö޺ͷÇÖÞµÄϵͳÉϼì²âµ½Î´¾ÊÚȨµÄ½Ó¼û¡£¡£¡£¡£¡£¡£¡£¡£ÀÕË÷ÍÅ»ïMedusaÒѽ«TFSÁÐÈëÆäÍøÕ¾£¬£¬£¬£¬£¬£¬£¬£¬²¢ÀÕË÷800ÍòÃÀÔªÒÔɾ³ýÊý¾Ý¡£¡£¡£¡£¡£¡£¡£¡£¹¥»÷Õß»¹¸øÁË·áÌï10ÌìµÄ¹¦·ò×ö³ö»ØÓ¦£¬£¬£¬£¬£¬£¬£¬£¬²¢Äܹ»Ñ¡ÔñÑÓ³Ö¾ÃÏÞ£¬£¬£¬£¬£¬£¬£¬£¬Ö»ÓÐÿÌìÖ§¸¶10000ÃÀÔª¡£¡£¡£¡£¡£¡£¡£¡£ÎªÁËÖ¤Ã÷ÈëÇÖ£¬£¬£¬£¬£¬£¬£¬£¬ºÚ¿ÍMedusa°ä²¼ÁËÔ̺¬²ÆÕþÎļþ¡¢µç×Ó±í¸ñºÍ²É°ì·¢Æ±µÈÊý¾ÝµÄÑù±¾¡£¡£¡£¡£¡£¡£¡£¡£´óÎÞÊýÎļþ¶¼ÊǵÂÓ£¬£¬£¬£¬£¬£¬£¬Åú×¢ºÚ¿Í³É¹¦½Ó¼ûÁË·áÌïÖÐÅ·ÒµÎñµÄϵͳ¡£¡£¡£¡£¡£¡£¡£¡£×êÑÐÈËԱй©£¬£¬£¬£¬£¬£¬£¬£¬Õâ´Î¹¥»÷¿ÉÄÜÓëCitrix GatewayµÄ·ì϶Óйء£¡£¡£¡£¡£¡£¡£¡£
https://securityaffairs.com/154319/data-breach/toyota-financial-services-medusa-ransomware.html
2¡¢ÑÅÂí¹þ·ÆÂɱö·Ö¹«Ë¾±»INC¹¥»÷Ô¼37GBµÄÊý¾Ýй¶
¾Ý11ÔÂ17ÈÕ±¨Â·£¬£¬£¬£¬£¬£¬£¬£¬ÑÅÂí¹þÆû³µ·ÆÂɱöĦÍгµÔì×÷·Ö¹«Ë¾(YMPH)Ôâµ½¹¥»÷£¬£¬£¬£¬£¬£¬£¬£¬²¿ÃÅÔ±¹¤ÐÅϢй¶¡£¡£¡£¡£¡£¡£¡£¡£YMPHÓÚ10ÔÂ25ÈÕ³õ´Î·¢ÏÖÎÊÌ⣬£¬£¬£¬£¬£¬£¬£¬Æäһ̨·þÎñÆ÷Ô⵽δ¾ÊÚȨµÄ½Ó¼û£¬£¬£¬£¬£¬£¬£¬£¬Ä¿Ç°ÔÚÆÀ¹ÀÕâ´Î¹¥»÷Ó°ÏìµÄÁìÓò¡£¡£¡£¡£¡£¡£¡£¡£ÀÕË÷ÍÅ»ïINCÐû³Æ¶Ô´ËÊÂÕÆ¹Ü£¬£¬£¬£¬£¬£¬£¬£¬ÓÚ11ÔÂ15ÈÕ½«¸Ã¹«Ë¾Ôö³¤µ½ÆäÍøÕ¾¡£¡£¡£¡£¡£¡£¡£¡£¶ûºó°ä²¼Á˶à¸öÎļþ£¬£¬£¬£¬£¬£¬£¬£¬ÆäÖÐÔ̺¬Ô¼Äª37GBµÄÊý¾Ý£¬£¬£¬£¬£¬£¬£¬£¬Éæ¼°Ô±¹¤IDÐÅÏ¢¡¢±¸·ÝÎļþÒÔ¼°¹«Ë¾ºÍÏúÊÛÐÅÏ¢µÈ¡£¡£¡£¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/yamaha-motor-confirms-ransomware-attack-on-philippines-subsidiary/
3¡¢BGRSºÍSIRVAÔâ¹¥»÷µ¼Ö¼ÓÄôóÊÐÕþ»ú¹¹´óÁ¿Ô±¹¤ÐÅϢй¶
¼ÓÄô󵱾ÖÔÚ11ÔÂ19ÈÕÅû¶Á˽üÆÚµÄÒ»´ÎÊý¾Ýй¶ÊÂÎñ£¬£¬£¬£¬£¬£¬£¬£¬Ó°ÏìÁËÏÖÈκÍǰÈι«¹²·þÎñ²¿ÃÅÔ±¹¤ÒÔ¼°¼ÓÄôó»Ê¼ÒÆï¾¯ºÍ¼ÓÄôóÎä×°¶ÓÁгÉÔ±¡£¡£¡£¡£¡£¡£¡£¡£Ä¿Ç°È·¶¨£¬£¬£¬£¬£¬£¬£¬£¬ÎªÔ±¹¤Ìṩ°áǨ·þÎñµÄBrookfield Global Relocation Services(BGRS)ºÍSIRVA Worldwide Relocation & Moving ServicesÊÇÕâ´ÎÊý¾Ýй¶ÊÂÎñµÄÔ´Í·¡£¡£¡£¡£¡£¡£¡£¡£¾ÝϤ£¬£¬£¬£¬£¬£¬£¬£¬Ô±¹¤×Ô1999ÄêÒÔÀ´ÏòÕâЩ¹«Ë¾ÌṩµÄÓ×ÎҺͲÆÕþÐÅÏ¢¿ÉÄÜÒѾй¶¡£¡£¡£¡£¡£¡£¡£¡£10ÔÂ6ÈÕ£¬£¬£¬£¬£¬£¬£¬£¬LockBit3.0½«SIRVAÔö³¤µ½ÁËÆäÍøÕ¾£¬£¬£¬£¬£¬£¬£¬£¬²¢ÓÚ11ÔÂ19ÈÕ¹«¿ªÁ˱»µÁÊý¾Ý¡£¡£¡£¡£¡£¡£¡£¡£BGRSÍøÕ¾×Ô9ÔÂ29ÈÕÆðÒ»Ïò´¦ÓÚÀëÏß״̬¡£¡£¡£¡£¡£¡£¡£¡£
https://www.databreaches.net/canadian-government-announces-data-breach-urges-public-service-employees-to-take-action/
4¡¢Google³ÆZimbra·ì϶CVE-2023-37580±»4¸öÍÅ»ïÀûÓÃ
11ÔÂ16ÈÕ£¬£¬£¬£¬£¬£¬£¬£¬Google TAGÅû¶ÁË4ÆðÀûÓÃZimbraÖеÄXSS·ì϶£¨CVE-2023-37580£©µÄ¹¥»÷»î¶¯¡£¡£¡£¡£¡£¡£¡£¡£µÚÒ»´Î»î¶¯²úÉúÓÚ6Ôµף¬£¬£¬£¬£¬£¬£¬£¬Õë¶ÔµÄÊÇÏ£À°Ä³µ±¾Ö»ú¹¹£¬£¬£¬£¬£¬£¬£¬£¬·¢ÏÖ·ì϶ºóZimbraÔÚGitHubÉÏÍÆËÍÁËÒ»¸ö´¹Î£½¨¸´·¨Ê½¡£¡£¡£¡£¡£¡£¡£¡£Winter VivernÓÚ7ÔÂ11ÈÕÀûÓø÷ì϶¹¥»÷ÁËĦ¶û¶àÍߺÍÍ»Äá˹ȷµ±¾Ö»ú¹¹£¬£¬£¬£¬£¬£¬£¬£¬ZimbraÔÚ7ÔÂ13ÈÕ°ä²¼°²È«²¼¸æ½¨ÒéÓû§²ÉÈ¡»º½â´ëÊ©¡£¡£¡£¡£¡£¡£¡£¡£7ÔÂ20ÈÕ£¬£¬£¬£¬£¬£¬£¬£¬Î´ÖªºÚ¿Í¹¥»÷ÁËÔ½ÄÏijµ±¾Ö»ú¹¹£¬£¬£¬£¬£¬£¬£¬£¬ÎåÌìºóZimbra°ä²¼Á˸÷ì϶µÄ¹Ù·½²¹¶¡¡£¡£¡£¡£¡£¡£¡£¡£8ÔÂ25£¬£¬£¬£¬£¬£¬£¬£¬TAG·¢ÏÖÁ˵Ú4´ÎÀûÓø÷ì϶µÄ¹¥»÷»î¶¯£¬£¬£¬£¬£¬£¬£¬£¬Õë¶Ô°Í»ù˹̹µ±¾Ö»ú¹¹¡£¡£¡£¡£¡£¡£¡£¡£
https://blog.google/threat-analysis-group/zimbra-0-day-used-to-target-international-government-organizations/
5¡¢8BaseÍÅ»ïͨ¹ýSmokeLoader·Ö·¢ÐµÄPhobos±äÌå
CiscoÔÚ11ÔÂ18Èճƣ¬£¬£¬£¬£¬£¬£¬£¬8Base½üÆÚµÄ»î¶¯ÓÐËùÔö³¤£¬£¬£¬£¬£¬£¬£¬£¬ËüʹÓÃÀÕË÷Èí¼þPhobosµÄ±äÌåºÍÆäËü¹«¿ª¿ÉÓõŤ¾ßÖ´Ðй¥»÷¡£¡£¡£¡£¡£¡£¡£¡£¸ÃÍÅ»ï´óÎÞÊýPhobos±äÌå¶¼ÊÇÓɺóÃÅSmokeLoader·Ö·¢µÄ¡£¡£¡£¡£¡£¡£¡£¡£ÔÚ8Base»î¶¯ÖУ¬£¬£¬£¬£¬£¬£¬£¬ËüÔÚ¼ÓÃܵÄpayloadÖÐǶÈëÁËÀÕË÷Èí¼þ×é¼þ£¬£¬£¬£¬£¬£¬£¬£¬¶øºó½«Æä½âÃܲ¢¼ÓÔØµ½SmokeLoader¹ý³ÌµÄÄÚ´æÖÓ×£¡£¡£¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬£¬£¬£¬Phobos¶Ô1.5MBÒÔϵÄÎļþÆëÈ«¼ÓÃÜ£¬£¬£¬£¬£¬£¬£¬£¬¶Ô³¬¹ýãÐÖµµÄÎļþ²¿ÃżÓÃÜ£¬£¬£¬£¬£¬£¬£¬£¬ÒÔÌá¸ßËÙ¶È¡£¡£¡£¡£¡£¡£¡£¡£
https://blog.talosintelligence.com/deep-dive-into-phobos-ransomware/
6¡¢Avast°ä²¼2023ÄêµÚÈý¼¾¶ÈµÄÍþÐ²Ì¬ÊÆµÄ·ÖÎö»ã±¨
11ÔÂ16ÈÕ£¬£¬£¬£¬£¬£¬£¬£¬Avast°ä²¼ÁË2023ÄêµÚÈý¼¾¶ÈµÄÍþÐ²Ì¬ÊÆµÄ·ÖÎö»ã±¨¡£¡£¡£¡£¡£¡£¡£¡£µÚÈý¼¾¶È£¬£¬£¬£¬£¬£¬£¬£¬Avast¾ùÔÈÿÔÂÀ¹½ØµÄ¶ñÒâÈí¼þ¹¥»÷³¬¹ý10ÒڴΣ¬£¬£¬£¬£¬£¬£¬£¬ÍøÂçÍþв£¨ÓÈÆäÊÇÉ繤¹¥»÷ºÍ¶ñÒâ¸æ°×£©µÄ´ó·ùÔö³¤Íƶ¯ÁËÕâÒ»Ôö³¤¡£¡£¡£¡£¡£¡£¡£¡£¹¥»÷Õß¶ÔÈËΪÖÇÄܵÄÀûÓÃÔڼӿ죬£¬£¬£¬£¬£¬£¬£¬ÓÈÆäÊÇÔÚÉî¶ÈαÔì½ðÈÚڿƻÖÓ×£¡£¡£¡£¡£¡£¡£¡£¸æ°×Èí¼þÏÔÖøÉý¼¶£¬£¬£¬£¬£¬£¬£¬£¬³ö¸ñÊÇÄÏÃÀ¡¢·ÇÖÞ¡¢¶«ÄÏÅ·ºÍ¶«ÑǵØÓò¡£¡£¡£¡£¡£¡£¡£¡£ÐÅÏ¢ÇÔÈ¡·¨Ê½µÄÍþвÔö³¤£¬£¬£¬£¬£¬£¬£¬£¬ÆäÖÐÎÚ¿ËÀ¼£¨44%£©¡¢ÃÀ¹ú£¨21%£©ºÍÓ¡¶È£¨16%£©µÄÔö·ù×îÏÔÖø¡£¡£¡£¡£¡£¡£¡£¡£RAT³ÖÐø³ÊÔö³¤Ç÷Ïò£¬£¬£¬£¬£¬£¬£¬£¬ÆÏÌÑÑÀ£¨148%£©¡¢²¨À¼£¨55%£©ºÍ˹Âå·¥¿Ë£¨43%£©µÈ¹úµÄÔö·ù×îÏÔÖø¡£¡£¡£¡£¡£¡£¡£¡£
https://decoded.avast.io/threatresearch/avast-q3-2023-threat-report/


¾©¹«Íø°²±¸11010802024551ºÅ